Innovexus runs as an appliance on infrastructure you own. It does not move your data anywhere, and it produces the access, change and monitoring evidence a compliance program needs — exportable at any time, straight from the box.
Innovexus does not itself hold a SOC 2, ISO 27001, or any other attestation, and it is not a hosted service that could inherit one. Because you run the appliance, the physical, network, and organisational controls of the environment are part of your compliance program — on your hardware, in your data center or cloud account. What the software gives you is the access controls and the evidence. The attestation is yours to pursue with your own auditor.
These ship in the product and operate entirely on your side of the wire.
AES-256-GCM at rest with per-appliance Fernet keys, automatic rotation every 24 hours. Operators never see or handle device passwords.
FIDO2 / passkey authentication over TLS 1.3. Each appliance mints its own keys on first boot — no shared secrets across deployments.
Every privileged action is recorded and streamed to your SIEM or syslog. Session recordings are captured on the appliance.
Credentials, recordings and logs stay on the appliance. Where the data lives is wherever you choose to run it — nothing is sent to a third party.
The appliance produces evidence mapped to the control families your auditors ask about.
Access control, change management and monitoring evidence: signed session recordings, credential-access logs, and configuration-change history exportable for your auditor.
Control mappings for access management (A.9), cryptography (A.10), and logging & monitoring (A.12). Evidence exports align to Annex A control families.
CIP-004 / CIP-005 / CIP-007 support: electronic access controls, interactive remote access recording, and audit logging for BES cyber systems.
IEC 62443-3-3 access-control and audit requirements for industrial networks — role-based privileges, session capture, and tamper-evident logs.
Questions about evidence scope or a specific control? Reach the team, or read how the platform works on the platform overview.